StackRadar

CVE-2026-73418

High

Advisory

Published 23 Jul 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
12
of 17,781 indexed, latest versions
Container images
12
deployed by those charts
Fix available
2 of 2
affected packages

Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers

Carried by container images the latest versions of 12 of 17,781 indexed charts deploy, on 12 images.

Affected packageAffected versionsFixed inImages
next-authnpm4.22.0, 4.24.5, 4.24.11, 4.24.14+1 more4.24.15, 5.0.0-beta.328
@auth/corenpm0.9.0, 0.27.0, 0.37.2, 0.41.20.41.36
OSV records
GHSA-xmf8-cvqr-rfgj

Charts affected

12 by stars
ChartLatestAffected imagesRadar Score
homarroben01Verified publisher1.4.01 of 1See more

homarr oben01 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-73418.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
next-auth@4.24.5
4.24.15

Open the chart page →

2,581
karakeephelmforgeVerified publisher1.2.91 of 3See more

karakeep helmforge 1.2.9

1 of the 3 container images this version deploys carry CVE-2026-73418.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
@auth/core@0.27.0
0.41.3

Open the chart page →

9,460
karakeepself-hosters-by-nightVerified publisher2.5.11 of 1See more

karakeep self-hosters-by-night 2.5.1

1 of the 1 container images this version deploys carry CVE-2026-73418.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
@auth/core@0.27.0
0.41.3

Open the chart page →

5,213
wraftwraft0.1.121 of 9See more

wraft wraft 0.1.12

1 of the 9 container images this version deploys carry CVE-2026-73418.

Container imageDigestPackageFixed in
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
next-auth@4.24.11
4.24.15

Open the chart page →

10,090
linkwardenadnoctemVerified publisher0.5.11 of 2See more

linkwarden adnoctem 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-73418.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
@auth/core@0.9.0
0.41.3

Open the chart page →

3,820
katalogalpineworks0.1.21 of 5See more

katalog alpineworks 0.1.2

1 of the 5 container images this version deploys carry CVE-2026-73418.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-frontend:v1.0.734b76dcb1c10
@auth/core@0.37.2
next-auth@5.0.0-beta.25
0.41.3
5.0.0-beta.32

Open the chart page →

4,497
documensodocumensoVerified publisher0.0.61 of 2See more

documenso documenso 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-73418.

Container imageDigestPackageFixed in
documenso/documenso:v1.8.17f16a9449f18
next-auth@4.24.5
4.24.15

Open the chart page →

2,862
portfolio-trackerkubernetes-homelab-helm-chartsVerified publisher0.1.01 of 3See more

portfolio-tracker kubernetes-homelab-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-73418.

Container imageDigestPackageFixed in
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
next-auth@4.24.14
4.24.15

Open the chart page →

1,498
lynxpromptlynxpromptVerified publisher0.1.21 of 3See more

lynxprompt lynxprompt 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-73418.

Container imageDigestPackageFixed in
drumsergio/lynxprompt:2.0.75c6afb6679301
@auth/core@0.41.2
next-auth@4.24.14
0.41.3
4.24.15

Open the chart page →

1,852
karakeeprtomik-helm-chartsVerified publisher0.0.11 of 3See more

karakeep rtomik-helm-charts 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-73418.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
@auth/core@0.27.0
0.41.3

Open the chart page →

5,338
homarrvhdirkVerified publisher0.1.51 of 1See more

homarr vhdirk 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-73418.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:lateste103abadfb52
next-auth@4.24.5
4.24.15

Open the chart page →

2,789
websitewaldo-visionVerified publisher0.33.01 of 2See more

website waldo-vision 0.33.0

1 of the 2 container images this version deploys carry CVE-2026-73418.

Container imageDigestPackageFixed in
ghcr.io/waldo-vision/web:v0.3.65bbc7647df07
next-auth@4.22.0
4.24.15

Open the chart page →

3,474

Container images carrying it

12 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
documenso/documenso:v1.8.17f16a9449f18
next-auth@4.24.5
4.24.15
1
drumsergio/lynxprompt:2.0.75c6afb6679301
@auth/core@0.41.2
next-auth@4.24.14
0.41.3
4.24.15
1
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
next-auth@4.24.5
4.24.15
1
ghcr.io/ajnart/homarr:lateste103abadfb52
next-auth@4.24.5
4.24.15
1
ghcr.io/alpineworks/katalog-frontend:v1.0.734b76dcb1c10
@auth/core@0.37.2
next-auth@5.0.0-beta.25
0.41.3
5.0.0-beta.32
1
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
next-auth@4.24.14
4.24.15
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
@auth/core@0.27.0
0.41.3
1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
@auth/core@0.27.0
0.41.3
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
@auth/core@0.27.0
0.41.3
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
@auth/core@0.9.0
0.41.3
1
ghcr.io/waldo-vision/web:v0.3.65bbc7647df07
next-auth@4.22.0
4.24.15
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
next-auth@4.24.11
4.24.15
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.